Bug#471670: [bzip2] CVE-2008-1372 buffer over-read via crafted archive file

2008-04-25 Thread Zoran Dzelajlija
Package: bzip2 Version: 1.0.5-0.1 --- Please enter the report below this line. --- Hi. This bug has been quiet for a while... I'm just pinging to see if there's any progress in fixing it in stable (and possibly oldstable). Regards, Zoran --- System information. --- Architecture: i386 Kernel:

Bug#471670: [bzip2] CVE-2008-1372 buffer over-read via crafted archive file

2008-04-25 Thread Thijs Kinkhorst
On Fri, April 25, 2008 13:08, Zoran Dzelajlija wrote: Hi. This bug has been quiet for a while... I'm just pinging to see if there's any progress in fixing it in stable (and possibly oldstable). Just a quick note: I'm not aware of progress for stable, but I can already note that no updates are

Bug#471670: [bzip2] CVE-2008-1372 buffer over-read via crafted archive file

2008-04-25 Thread Luis Uribe
Hi, I made a [1]package for stable that will close the bug. And i've contacted the Security Team, but since there is no code injection they consider it a normal bug, so i probably it will be uploaded to stable-proposed. However i didn't finished yet with the tests, so i'm not pretty sure that

Bug#471670: bzip2: CVE-2008-1372 buffer over-read via crafted archive file

2008-03-19 Thread Nico Golde
Package: bzip2 Severity: grave Tags: security Hi, the following CVE (Common Vulnerabilities Exposures) id was published for bzip2. CVE-2008-1372[0]: | bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to | cause a denial of service (crash) via a crafted file that triggers a |